Malicious PDF — malware analysis report

Static analysis result for SHA-256 3944211051dbe5dd…

MALICIOUS

PDF

76.6 KB Created: 2021-03-19 16:08:52 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 41ab3ff11fa43452ab021089a1525cff SHA-1: 2d81199eac3ae04cbc1926807a53df0b55bf5a2c SHA-256: 3944211051dbe5dd80d7f44513135d797b0303f0baf51974bce20dbca1034594
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a large number of external links, many of which are embedded within the document body and disguised as tutorial resources. The ClamAV detection and ML classifier strongly indicate malicious intent, likely phishing or a link farm for malicious sites. No scripts were extracted, but the presence of numerous external URIs suggests a phishing or redirection attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/123?utm_term=adobe+after+effects+tutorial+videos+free
    • https://static.s123-cdn-static.com/uploads/4497697/normal_5fee8dcff3ddc.pdf
    • https://cdn-cms.f-static.net/uploads/4448556/normal_6049080d81c75.pdf
    • https://cdn.sqhk.co/senosekagoko/gchhXRQ/duwixugadumikasefin.pdf
    • https://cdn-cms.f-static.net/uploads/4405674/normal_602091adac021.pdf
    • https://cdn.sqhk.co/sugigevapure/jeElSja/mermaid_photoshop_deviantart.pdf
    • https://cdn-cms.f-static.net/uploads/4412382/normal_6011e75186d8b.pdf
    • https://cdn.sqhk.co/xomifinetepi/yjehchj/71210333163.pdf
    • https://static.s123-cdn-static.com/uploads/4450727/normal_5fdebd93b7591.pdf
    • https://cdn.sqhk.co/kinibemazoz/fjfifij/nasal_spray_covid_ucsf.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/jolunenafobuw/eddie_the_eagle_parents_guide.pdf
    • https://s3.amazonaws.com/xewamejixolefaj/99488200005.pdf
    • https://2dc0326d-ac60-47d8-bf46-f2dc9d334570.filesusr.com/ugd/21b4a7_4bb3b7efd9d54a5bb39f87dfd6316140.pdf?index=true
    • https://s3.amazonaws.com/nemafu/filawejatedipumupasexa.pdf
    • https://s3.amazonaws.com/vexeliku/ms_sql_server_2017.pdf
    • https://s3.amazonaws.com/telasebisu/34662943748.pdf
    • https://fe426b01-1dd0-498a-b08e-7ec37e320b94.filesusr.com/ugd/6b45f0_4d4d0d114a634944b3a5a5ab0fdee8a4.pdf?index=true
    • https://5d3a357a-25b2-4459-9cd8-210b235f7b36.filesusr.com/ugd/45e30f_d316b004bc304ceaa1f2acaf44bd9fa0.pdf?index=true
    • https://s3.amazonaws.com/galinikagopit/35255065855.pdf
    • https://s3.amazonaws.com/zozofufulolig/fdmr_my_name_ringtone_free.pdf
    • https://s3.amazonaws.com/benubapopikaj/kogilolujizegurukudu.pdf
    • https://s3.amazonaws.com/norozovijalu/chromecast_extension_for_pc.pdf
    • https://s3.amazonaws.com/kovibu/gesakituxekuperedamup.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ef48.bin
f5e482597e0d906022dda128fbf7d318695f655cda2048ca5e52b7572c018aa9
pdf-font-stream PDF embedded font (sfnt) at offset 0xEF48 5204 bytes
font_01_sfnt_off00010116.bin
9dfb77dd640cf6221a2124c3669287a433c4c82fdca0488f69819b15845fb41b
pdf-font-stream PDF embedded font (sfnt) at offset 0x10116 10620 bytes